News
23 Apr 2026, 19:45
Kelp DAO Exploit: Chainalysis Confirms Off-Chain Attack, Not a Smart Contract Bug – Critical Security Lesson

BitcoinWorld Kelp DAO Exploit: Chainalysis Confirms Off-Chain Attack, Not a Smart Contract Bug – Critical Security Lesson New York, USA – March 5, 2025 – Blockchain analytics firm Chainalysis has released a detailed report confirming that the recent $292 million Kelp DAO bridge exploit was not a smart contract bug. Instead, the attack targeted off-chain infrastructure. This finding changes how the crypto community understands the incident. It also raises urgent questions about security beyond the blockchain. Kelp DAO Exploit: A $292 Million Wake-Up Call The Kelp DAO exploit occurred on February 28, 2025. Attackers drained approximately $292 million from the protocol’s bridge. Initial reports speculated about a vulnerability in the smart contract code. However, Chainalysis now provides clarity. The firm’s investigation reveals a different story. According to the report, the hacker manipulated off-chain systems. They tricked the bridge into issuing rsETH tokens. This happened even though the corresponding assets had not been burned on the source chain. In simple terms, the attacker created rsETH out of thin air. They did this by compromising the backend infrastructure that validates cross-chain transactions. Chainalysis states that the attack exploited weaknesses in the bridge’s off-chain relay and validation logic. These components are responsible for verifying that assets are locked or burned before minting on the destination chain. The hacker bypassed these checks. This allowed them to mint rsETH without providing real collateral. The exploit underscores a growing trend in crypto security. Off-chain infrastructure is becoming a prime target. Smart contracts are audited and hardened. But the systems that connect them remain vulnerable. This incident is a stark reminder that security must extend to all layers of a protocol. How the Off-Chain Attack Worked Chainalysis provides a step-by-step breakdown of the Kelp DAO exploit. The attack did not require exploiting a smart contract bug. Instead, it targeted the bridge’s off-chain components. Step 1: Reconnaissance. The attacker studied the bridge’s off-chain relay system. They identified weaknesses in the validation process. Step 2: Compromise. The hacker gained access to the off-chain infrastructure. This likely involved exploiting a vulnerability in a server or API. Step 3: Manipulation. They submitted a fake proof of asset burn. The off-chain relay accepted this without proper verification. Step 4: Minting. The bridge minted 10,000 rsETH tokens on the destination chain. These tokens had no backing. Step 5: Liquidation. The attacker swapped the fake rsETH for other assets. They then moved the funds through mixers and exchanges. This sequence highlights a critical gap. The bridge trusted the off-chain relay completely. It did not require on-chain verification of the burn event. The attacker exploited this trust. Chainalysis Report: Key Findings The Chainalysis report offers several key insights. First, the smart contract code was not the problem. Auditors had reviewed it. No critical bugs existed. Second, the off-chain infrastructure lacked redundancy. A single point of failure led to the entire exploit. Third, the attack was sophisticated. It required deep knowledge of bridge architecture. Chainalysis also notes that the attacker likely had insider knowledge. They understood the relay system’s internal logic. This suggests a targeted attack rather than a random hack. The firm recommends that protocols implement multi-signature validation for off-chain operations. They also suggest using cryptographic proofs to verify cross-chain messages. The report emphasizes that off-chain attacks are harder to detect. They leave fewer on-chain traces. Traditional security tools focus on smart contracts. They miss vulnerabilities in backend systems. This incident will likely accelerate investment in off-chain security solutions. Impact on the Crypto Ecosystem The Kelp DAO exploit has immediate and long-term impacts. In the short term, the protocol lost $292 million. This represents a significant portion of its total value locked. Users who held rsETH faced uncertainty. The token’s price dropped sharply. Some decentralized exchanges paused trading. Kelp DAO has since taken steps to recover. They paused the bridge and initiated a security review. They also offered a bounty for information leading to the hacker. However, full recovery remains uncertain. The stolen funds may never be returned. In the long term, this incident will reshape security practices. Protocols will now scrutinize their off-chain infrastructure. They will implement stronger access controls. They will also use more robust validation mechanisms. The industry may see new standards for bridge security. Regulators are also paying attention. The exploit highlights the risks of cross-chain bridges. These bridges are critical for interoperability. But they also create new attack surfaces. Policymakers may push for stricter requirements. This could include mandatory audits of off-chain systems. Lessons for Developers and Users Developers must learn from the Kelp DAO exploit. Smart contract audits are not enough. Off-chain components need equal scrutiny. This includes relay servers, APIs, and validator nodes. Each component represents a potential entry point for attackers. Users should also exercise caution. They should research a protocol’s security posture. They should look for evidence of off-chain audits. They should also consider the protocol’s response to incidents. Transparency and speed matter in a crisis. The exploit also underscores the importance of decentralization. Centralized off-chain components create single points of failure. Protocols should aim to decentralize these components. This reduces the risk of a single compromise leading to a massive loss. Comparing the Kelp DAO Exploit to Other Attacks The Kelp DAO exploit is not the first off-chain attack. However, it is one of the largest. Previous incidents include the Ronin Bridge hack and the Wormhole exploit. Both involved off-chain vulnerabilities. The Ronin attack compromised validator keys. The Wormhole exploit targeted a bridge contract. Each incident offers unique lessons. Attack Amount Lost Attack Vector Year Kelp DAO $292M Off-chain relay compromise 2025 Ronin Bridge $625M Validator key compromise 2022 Wormhole $326M Smart contract vulnerability 2022 Poly Network $611M Cross-chain message manipulation 2021 This table shows a pattern. Off-chain and cross-chain vulnerabilities are common. They often lead to large losses. The Kelp DAO exploit fits this pattern. It also highlights the evolving nature of these attacks. Attackers are becoming more sophisticated. They target the weakest link in the chain. Conclusion The Kelp DAO exploit serves as a critical security lesson for the entire crypto industry. Chainalysis confirms that the $292 million loss resulted from an off-chain attack, not a smart contract bug. This distinction is vital. It forces protocols to look beyond the blockchain. They must secure every component of their infrastructure. The incident also underscores the need for better validation mechanisms. Multi-signature verification and cryptographic proofs can prevent similar attacks. As the industry grows, security must evolve. The Kelp DAO exploit is a reminder that no system is safe without comprehensive protection. Developers, users, and regulators must all take note. FAQs Q1: What was the Kelp DAO exploit? A1: The Kelp DAO exploit was a $292 million attack on the protocol’s bridge. Attackers manipulated off-chain infrastructure to mint fake rsETH tokens. Chainalysis confirmed it was not a smart contract bug. Q2: How did the off-chain attack work? A2: The hacker compromised the bridge’s off-chain relay system. They submitted a fake proof of asset burn. The relay accepted it without proper verification. This allowed the minting of unbacked rsETH tokens. Q3: What did Chainalysis find in their report? A3: Chainalysis found that the exploit targeted off-chain infrastructure, not smart contracts. They identified weaknesses in the relay validation process. They recommended multi-signature verification and cryptographic proofs. Q4: What are the impacts of the Kelp DAO exploit? A4: The protocol lost $292 million. rsETH token price dropped sharply. The incident has led to increased scrutiny of off-chain security. It may also influence regulatory approaches to bridge security. Q5: How can protocols prevent similar attacks? A5: Protocols should audit all off-chain components. They should implement multi-signature validation for cross-chain operations. They should also use cryptographic proofs to verify messages. Decentralizing off-chain infrastructure reduces single points of failure. This post Kelp DAO Exploit: Chainalysis Confirms Off-Chain Attack, Not a Smart Contract Bug – Critical Security Lesson first appeared on BitcoinWorld .
23 Apr 2026, 19:44
Dogecoin Price Analysis: $0.1018 Resistance Holds as Whales Accumulate

Dogecoin continues to trade below the critical $0.1018 resistance after multiple failed breakout attempts. The level has rejected price five times, strengthening its role as a key barrier in the current structure. At the time of writing, Dogecoin trades at $0.09625, reflecting ongoing downtrend momentum amid active selling pressure. Price action remains confined within a parallel channel, suggesting limited directional movement. Resistance Limits Upside Momentum The $0.1018 level has become a strong ceiling on the four-hour chart. Each rally toward this point has met consistent resistance, preventing any sustained upward movement. This repeated rejection has increased caution among traders. Analysts note that a confirmed four-hour close above $0.1018 is required to shift sentiment. Volume remains a key factor. Without strong participation, any breakout attempt risks failure. The current channel continues to compress prices into a narrow band. Such formations often lead to sharp moves once the range breaks. However, direction remains uncertain at this stage. Sellers continue to defend resistance aggressively. This adds pressure on each upward attempt. A clear break above the level would likely trigger a change in short-term positioning. Whale Accumulation Signals Potential Shift On-chain data presents a contrasting view. Transaction volume recently surged, with nearly $800 million in DOGE moved within a single day. This marks one of the highest activity levels recorded this year. Large holders have also increased exposure. Whales accumulated over $330 million worth of Dogecoin in the past week. This activity suggests growing interest despite the ongoing consolidation. The divergence between price and on-chain metrics remains notable. While price action shows weakness, underlying demand appears to be building. This pattern has historically preceded strong moves. If Dogecoin manages to clear $0.1018 with rising volume, the next target stands near $0.1172. This level aligns with the upper boundary of the current channel. For now, the asset remains at a key decision point. The next move will likely define the short-term trend.
23 Apr 2026, 19:43
XRP tops $1.43 as whale demand surges

🚀 XRP jumped past $1.43 as whale activity spiked. Big buyers are driving accumulation, while sellers fade away. Continue Reading: XRP tops $1.43 as whale demand surges The post XRP tops $1.43 as whale demand surges appeared first on COINTURK NEWS .
23 Apr 2026, 19:40
BIS talks about the rapid evolution of cryptoasset service providers

The BIS, famously known as the central bank of central banks, highlighted the need for appropriate safeguards as cryptoasset service providers have stopped being fringe aspects of global finance to become real financial intermediaries in its latest paper. The post comes close to the end of an active month for DeFi hackers. Two of the biggest scandals to shake the DeFi space this year illustrate the contagion risk mentioned in the paper posted by the BIS. BIS talks about the rapid evolution of cryptoasset service providers The paper acknowledged how the capabilities of cryptoasset service providers have expanded beyond their initial roles as trading platforms and custodial service providers. It presented a new classification, multifunction cryptoasset intermediaries (MCIs), in its expression of how some of the products these firms now offer closely resemble financial intermediation activities that used to be the exclusive domain of banks and prime brokers. According to the paper, MCIs take on credit, liquidity, and maturity risk when they accept customer cryptoassets via investment programs and use those assets to fund lending, market making, and other activities. This puts them virtually on the same level as traditional financial intermediaries. However, the paper suggests that despite this, in many jurisdictions, MCIs operate without prudential safeguards. Meanwhile, these safeguards, like deposit insurance and central bank liquidity, apply to their traditional financial counterparts engaged in comparable risk transformation. This helps MCIs get away with things like opacity, which leads to significant data gaps. The BIS also noted that now that TradFi and crypto are integrating, the risk of spillover effects has become more real. To address these risks, the BIS proposed a tandem of entity-based (EB) and activity-based (AB) regulations, even though it admitted challenges that could make that route difficult. Some of the challenges the organization mentioned in the paper were lags in coverage of borrowing and lending activities happening within existing cryptoasset regulatory frameworks, the need for effective cross-border supervisory cooperation, and limited supervisory resources. The DeFi market has been through the wringer There is no doubt that the DeFi sector has been wracked with some pretty scandalous exploits, as losses from this month alone have almost 4X the total for the first three months of the year. The latest scandal, a great example of contagion risk, involved KelpDAO, where attackers exploited a vulnerability in the protocol’s verification layer. This allowed them to mint about 116,500 rsETH out of thin air, which they then used to borrow ETH from major lending platforms like Aave. When markets realized the con, the value of rsETH collapsed, and lenders were left holding the bag. About $292 million was drained as a result, and Aave, as well as other lending protocols, were forced to suspend operations to prevent a systemic run on their liquidity pools. Hackers extracted about $285 million from the Drift exploit this month as well. These scandals have shown that DeFi needs to rely on something other than code. KelpDAO loot has crossed over to Bitcoin According to security analysts at Halborn, the recent KelpDAO exploit has links to the Lazarus Group from North Korea. This was backed up by sleuths like ZachXBT and Tayvano on X, with Tayvano sharing in a tweet earlier today that the DPRK was involved and that the money has been completely laundered via Thorchain. Her post came after it was revealed that the KelpDAO hackers took 1.5 days to swap nearly all of their 75,700 ETH holdings into BTC. According to reports, most of this occurred on THORChain, which amounted to about roughly $910,000 in platform fee revenue, reminiscent of the notoriety that the platform gained in February 2025 when the same suspected group laundered the loot from the Bybit $1.5 billion hack through the same venue. The smartest crypto minds already read our newsletter. Want in? Join them .
23 Apr 2026, 19:40
Asia FX Consolidates Cautiously as War Powers Deadline Looms: DBS Analysis

BitcoinWorld Asia FX Consolidates Cautiously as War Powers Deadline Looms: DBS Analysis Asian foreign exchange (Asia FX) markets enter a phase of cautious consolidation as the War Powers deadline approaches, according to DBS Group Research. Investors remain on edge, weighing geopolitical risks against regional economic fundamentals. This article provides a detailed analysis of the current state of Asia FX, the factors driving consolidation, and the potential impacts of the upcoming deadline. Asia FX Consolidation: Key Drivers and Market Sentiment The War Powers deadline creates a significant overhang for Asia FX markets. DBS analysts highlight that this deadline triggers a reassessment of risk across the region. Consequently, currencies such as the Singapore dollar (SGD), South Korean won (KRW), and Thai baht (THB) show limited directional bias. The consolidation reflects a wait-and-see approach among traders. Many participants reduce exposure to avoid sudden volatility. This cautious stance stems from the potential for new sanctions or diplomatic actions. The deadline acts as a catalyst for this risk-off behavior. It forces market participants to recalibrate their positions. DBS notes that the consolidation is orderly, not panicked. This suggests that markets price in a range of outcomes. However, the uncertainty remains high. Short-term volatility could spike if the deadline passes without clear resolution. The focus keyword, Asia FX, appears prominently in this analysis. DBS Research: Expert Insights on Currency Trends DBS provides a nuanced view of the Asia FX landscape. The bank’s research team emphasizes that the consolidation is not uniform across all currencies. Some currencies show relative strength due to domestic factors. For example, the Indonesian rupiah (IDR) benefits from strong commodity exports. Meanwhile, the Philippine peso (PHP) faces pressure from rising import costs. DBS uses a fundamental analysis framework to assess these divergences. They examine trade balances, inflation rates, and central bank policies. The War Powers deadline adds an external shock to this mix. It amplifies existing vulnerabilities. DBS advises clients to focus on carry trades with high-yielding currencies. However, they caution against excessive risk-taking. The bank’s expertise provides a trusted guide for navigating these uncertain times. Their analysis incorporates real-world data and historical precedents. This adds depth to the market commentary. Regional Central Bank Responses to the Deadline Central banks across Asia respond to the War Powers deadline with varying strategies. The Bank of Korea (BOK) maintains a cautious tone. It signals readiness to intervene if the won depreciates sharply. The Monetary Authority of Singapore (MAS) uses its exchange rate-based policy to manage volatility. The Bank of Thailand (BOT) keeps interest rates steady. These responses reflect a common goal: maintaining financial stability. The deadline forces central banks to balance domestic needs with external risks. Some analysts expect coordinated actions if the deadline triggers a crisis. However, DBS believes that individual responses will suffice. The region’s strong foreign reserves provide a buffer. This reduces the likelihood of a systemic event. Nonetheless, the situation remains fluid. Traders should monitor central bank statements closely. Geopolitical Context: War Powers and Regional Stability The War Powers deadline stems from a legislative requirement for the executive branch to report on military engagements. This deadline affects Asia FX through its impact on risk appetite. Historically, such deadlines create short-term uncertainty. However, their long-term effects depend on the outcome. The current deadline relates to ongoing tensions in the region. These tensions involve multiple stakeholders. The potential for escalation weighs on investor sentiment. Asia FX markets reflect this through lower trading volumes and tighter ranges. DBS notes that the deadline is a known event. Markets have time to prepare. This reduces the chance of a disorderly reaction. Nevertheless, the geopolitical backdrop remains complex. Trade disputes and territorial claims add layers of risk. The deadline acts as a focal point for these broader issues. Impact on Major Asia FX Pairs: USD/SGD, USD/KRW, USD/THB The impact of the War Powers deadline varies across major Asia FX pairs. The USD/SGD pair trades in a narrow range. The Singapore dollar benefits from the country’s safe-haven status. However, the deadline caps any significant appreciation. The USD/KRW pair shows more volatility. The won is sensitive to geopolitical news. The deadline creates a risk premium for the Korean currency. The USD/THB pair reflects Thailand’s tourism-dependent economy. The deadline adds to existing pressures from slow tourism recovery. DBS provides specific forecasts for these pairs. They expect the SGD to remain resilient. The KRB could weaken if tensions escalate. The THB may stay under pressure. These projections help traders plan their strategies. The analysis uses historical data to support these views. Trade and Investment Implications of the Consolidation The cautious consolidation in Asia FX has direct implications for trade and investment. Exporters in the region face uncertain currency conditions. A stable currency helps with pricing and planning. However, the consolidation limits the ability to hedge effectively. Importers benefit from reduced volatility. They can lock in favorable rates. Investors in Asian equities also watch currency moves closely. A weaker local currency erodes returns for foreign investors. The deadline adds a layer of complexity to investment decisions. DBS advises a diversified approach. They recommend focusing on currencies with strong fundamentals. The bank also suggests using options to manage risk. These strategies help navigate the current environment. The consolidation may persist until the deadline passes. After that, markets could see a clearer direction. Historical Precedents: How Asia FX Reacted to Past Deadlines Historical data shows that Asia FX markets react to similar deadlines with a pattern of consolidation followed by a breakout. Past events, such as the 2023 debt ceiling debate, caused temporary risk aversion. Currencies in the region weakened initially. However, they recovered once the deadline passed without major disruption. DBS draws parallels to the current situation. They note that the War Powers deadline is different. It involves military action, not fiscal policy. This makes the outcome less predictable. Nonetheless, the pattern of consolidation is consistent. Markets tend to price in the worst-case scenario. If the deadline passes peacefully, currencies could strengthen. If tensions escalate, a sell-off is possible. This historical context helps traders set expectations. It also highlights the importance of monitoring news flow. Technical Analysis: Chart Patterns in Asia FX Technical indicators support the view of consolidation in Asia FX. Charts show tight ranges and declining volatility. The USD/SGD pair forms a symmetrical triangle pattern. This suggests an impending breakout. The USD/KRW pair tests key support levels. A break below could trigger further weakness. The USD/THB pair shows a bearish flag formation. DBS uses these patterns to inform their forecasts. They emphasize that technicals align with fundamentals. The consolidation reflects a market in equilibrium. However, this equilibrium is fragile. A catalyst, such as the War Powers deadline, could break it. Traders should watch for volume spikes. These often precede significant moves. The analysis provides actionable insights for short-term traders. It also reinforces the broader narrative of caution. Conclusion: Navigating Asia FX Through the Deadline Asia FX markets enter a period of cautious consolidation as the War Powers deadline approaches. DBS research provides a comprehensive framework for understanding this phase. The consolidation reflects a balance of risks. Geopolitical uncertainty limits upside. Strong fundamentals provide a floor. Central banks stand ready to act. Traders should remain vigilant. The deadline could trigger volatility. However, the region’s resilience offers some comfort. The focus keyword, Asia FX, remains central to this analysis. Investors should use this time to reassess their positions. A diversified strategy helps manage risk. The outcome of the deadline will shape the next trend. For now, caution prevails. The markets wait for clarity. This article provides the insights needed to navigate these uncertain times. FAQs Q1: What is the War Powers deadline and how does it affect Asia FX? The War Powers deadline is a legislative requirement for the executive branch to report on military engagements. It affects Asia FX by increasing geopolitical uncertainty, leading to cautious consolidation as traders reduce risk exposure. Q2: Which Asia FX currencies are most impacted by the deadline? Currencies like the South Korean won (KRW), Thai baht (THB), and Singapore dollar (SGD) are most impacted. The won is sensitive to geopolitical news, while the baht faces tourism-related pressures. The SGD benefits from safe-haven flows. Q3: How does DBS recommend navigating the current Asia FX environment? DBS recommends a diversified approach, focusing on currencies with strong fundamentals. They suggest using options to manage risk and advise clients to focus on carry trades with high-yielding currencies while avoiding excessive risk-taking. Q4: What historical patterns exist for Asia FX during similar deadlines? Historically, Asia FX markets show a pattern of consolidation followed by a breakout. Past events, like the 2023 debt ceiling debate, caused temporary weakness but recovery after the deadline passed without disruption. The current situation is less predictable due to military implications. Q5: What are the key technical patterns to watch in Asia FX? Key technical patterns include a symmetrical triangle in USD/SGD, support tests in USD/KRW, and a bearish flag in USD/THB. These patterns suggest impending breakouts, with the War Powers deadline acting as a potential catalyst. Q6: How should investors prepare for potential volatility after the deadline? Investors should monitor central bank statements, use hedging strategies like options, and maintain a diversified portfolio. DBS advises focusing on currencies with strong foreign reserves and avoiding overexposure to high-risk pairs. This post Asia FX Consolidates Cautiously as War Powers Deadline Looms: DBS Analysis first appeared on BitcoinWorld .
23 Apr 2026, 19:36
Arbitrum freezes over 30,000 ETH after KelpDAO exploit

🚨 Over 30,000 ETH frozen in $ETH after the KelpDAO hack. The Arbitrum Security Council took urgent action to lock funds. Continue Reading: Arbitrum freezes over 30,000 ETH after KelpDAO exploit The post Arbitrum freezes over 30,000 ETH after KelpDAO exploit appeared first on COINTURK NEWS .

















































